HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 176

Dynamic IPv4 source guard using DHCP snooping configuration example, Network requirements

Page 176 highlights

# On Ten-GigabitEthernet 1/1/6, configure a static IPv4 source guard binding entry to allow only IP packets with the source MAC address of 0001-0203-0406 and the source IP address of 192.168.0.1 to pass. [SwitchB-Ten-GigabitEthernet1/1/6] ip source binding ip-address 192.168.0.1 mac-address 0001-0203-0406 [SwitchB-Ten-GigabitEthernet1/1/6] quit # Enable IPv4 source guard on port Ten-GigabitEthernet 1/1/5. [SwitchB] interface ten-gigabitEthernet 1/1/5 [SwitchB-Ten-GigabitEthernet1/1/5] ip verify source ip-address mac-address # On Ten-GigabitEthernet 1/1/5, configure a static IPv4 source guard binding entry to allow only IP packets with the source MAC address of 0001-0203-0407 and the source IP address of 192.168.0.2 to pass. [SwitchB-Ten-GigabitEthernet1/1/5] ip source binding ip-address 192.168.0.2 mac-address 0001-0203-0407 [SwitchB-Ten-GigabitEthernet1/1/5] quit 3. Verify the configuration: # Display static IPv4 source guard binding entries on Switch A. The output shows that the static IPv4 source guard binding entries are configured successfully. display ip source binding static Total entries found: 2 IP Address MAC Address Interface VLAN Type 192.168.0.1 0001-0203-0405 XGE1/1/6 N/A Static 192.168.0.3 0001-0203-0406 XGE1/1/5 N/A Static # Display static IPv4 source guard binding entries on Switch B. The output shows that the static IPv4 source guard binding entries are configured successfully. display ip source binding static Total entries found: 2 IP Address MAC Address Interface VLAN Type 192.168.0.1 0001-0203-0406 XGE1/1/6 N/A Static 192.168.0.2 0001-0203-0407 XGE1/1/5 N/A Static Dynamic IPv4 source guard using DHCP snooping configuration example Network requirements As shown in Figure 58, the host (the DHCP client) obtains an IP address from the DHCP server. Enable DHCP snooping on the switch, so that the host can obtain an IPv4 address from the valid DHCP server and the IPv4 address and the MAC address of the host can be recorded in a DHCP snooping entry. Enable dynamic IPv4 source guard on port Ten-GigabitEthernet 1/1/5 to filter received packets based on DHCP snooping entries, allowing only packets from a client that obtains an IP address from the DHCP server to pass. 167

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

167
# On Ten-GigabitEthernet 1/1/6, configure a static IPv4 source guard binding entry to allow only
IP packets with the source MAC address of 0001-0203-0406 and the source IP address of
192.168.0.1 to pass.
[SwitchB-Ten-GigabitEthernet1/1/6] ip source binding ip-address 192.168.0.1
mac-address 0001-0203-0406
[SwitchB-Ten-GigabitEthernet1/1/6] quit
# Enable IPv4 source guard on port Ten-GigabitEthernet 1/1/5.
[SwitchB] interface ten-gigabitEthernet 1/1/5
[SwitchB-Ten-GigabitEthernet1/1/5] ip verify source ip-address mac-address
# On Ten-GigabitEthernet 1/1/5, configure a static IPv4 source guard binding entry to allow only
IP packets with the source MAC address of 0001-0203-0407 and the source IP address of
192.168.0.2 to pass.
[SwitchB-Ten-GigabitEthernet1/1/5] ip source binding ip-address 192.168.0.2
mac-address 0001-0203-0407
[SwitchB-Ten-GigabitEthernet1/1/5] quit
3.
Verify the configuration:
# Display static IPv4 source guard binding entries on Switch A. The output shows that the static
IPv4 source guard binding entries are configured successfully.
<SwitchA> display ip source binding static
Total entries found: 2
IP Address
MAC Address
Interface
VLAN Type
192.168.0.1
0001-0203-0405 XGE1/1/6
N/A
Static
192.168.0.3
0001-0203-0406 XGE1/1/5
N/A
Static
# Display static IPv4 source guard binding entries on Switch B. The output shows that the static IPv4
source guard binding entries are configured successfully.
<SwitchB> display ip source binding static
Total entries found: 2
IP Address
MAC Address
Interface
VLAN Type
192.168.0.1
0001-0203-0406 XGE1/1/6
N/A
Static
192.168.0.2
0001-0203-0407 XGE1/1/5
N/A
Static
Dynamic IPv4 source guard using DHCP snooping
configuration example
Network requirements
As shown in
Figure 58
, the host (the DHCP client) obtains an IP address from the DHCP server.
Enable DHCP snooping on the switch, so that the host can obtain an IPv4 address from the valid DHCP
server and the IPv4 address and the MAC address of the host can be recorded in a DHCP snooping
entry.
Enable dynamic IPv4 source guard on port Ten-GigabitEthernet 1/1/5 to filter received packets based
on DHCP snooping entries, allowing only packets from a client that obtains an IP address from the DHCP
server to pass.